Support capturing/tracing unix domain sockets with kprobe ebpf #225
Labels
area/ebpf
area/plugins
help wanted
Extra attention is needed
priority/1
P1
type/enhancement
New feature or request
Today Retina only watches for events from either tc prog or some drop reason kprobes, Retina should be watching for events of unix domain socket as well. This will need additional work to understand how to distinguish src and dest pod/container/process.
For starters, attaching to below kprobes:
kprobe/unix_stream_sendmsg
kprobe/unix_dgram_sendmsg
fentry/unix_stream_sendmsg
fentry/unix_dgram_sendmsg
Example:
https://github.com/Asphaltt/sockdump
The text was updated successfully, but these errors were encountered: